CVE-2021-21602

MEDIUM6.5EPSS 1.7%

Arbitrary file read vulnerability in workspace browsers in Jenkins

Published: 5/24/2022Modified: 4/3/2025

Description

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows reading arbitrary files using the file browser for workspaces and archived artifacts by following symlinks.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

References (4)